CVE-2026-87637
A use-after-free vulnerability in Google Chrome's Extensions component on macOS allows a remote attacker to execute arbitrary code outside the sandbox by tricking a user into visiting a crafted HTML page. The flaw affects Chrome versions prior to 153.0.8010.36 and has a CVSS base score of 9.6 (critical). No known exploitation or public exploit has been reported.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Google Chrome on macOS versions before 153.0.8010.36
Real-world impact
An attacker could bypass the browser sandbox and run arbitrary code on the victim's machine, potentially leading to full system compromise.
Why this severity
The CVSS v3.1 score of 9.6 reflects a network‑attackable flaw with low complexity, no privileges required, user interaction needed, and high impacts to confidentiality, integrity, and availability.
What to do about it
- 011. Update Google Chrome on macOS to version 153.0.8010.36 or later.
NVD description
Timeline
- Sep 9, 2026 · 5d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 9, 2026 · 4d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- chromereleases.googleblog.com/2026/09/stable-channel-upda…release notesvendor advisory
- issues.chromium.org/issues/534863145permissions required